spec: seed the 4.2 candidate with the slot-disposition scoping (#42) - #70
Conversation
…las-Keystate#42) Section 8 claims a verifier that can evaluate a rotation can evaluate a quorum of endorsements. The threshold algebra does transfer; the satisfaction predicate does not - at the key tier a slot is filled by a verified signature at a key-list offset, at the evidence tier by a cross-log check on a committed endorsement. The seed scopes the claim to the algebra and completes the pending-discharge clause beneath it, which says 'unfilled slots' where the cited grammar has three dispositions and a declined slot is never cured by waiting. It also records what neither repair closes: which section 7.2 species a slot disposition maps to is unstated, and under R3 species is a component of the canonical order, so the mapping is a byte-identity exposure of finding Nicholas-Keystate#27's class. Signed-off-by: Daniel Hardman <daniel.hardman@gmail.com>
Supplement 3 adjudicates the same sentence this seed repairs, after the integration round's two legs reached opposite verdicts on it and the authority scoped the claim to analogous constructions. The replacement adopts the ruling's word and its shape: one satisfaction shape over slot judgments of different kinds, the slot judgment named as this document's own fold question, and the forward clause that upgrades the analogy to a declared shared dependency by ordinary migration once the shared predicate exists upstream. The translation profile routes to the encoding round. Also records a factual caution the adjudication's parenthetical could obscure: the reference implementation's one-class observation describes a shape, not an exercised path - no m-ary or threshold edge-group operator exists under src/keri at c63726654 - which is the overclaim this repair removes. Signed-off-by: Daniel Hardman <daniel.hardman@gmail.com>
|
S3-1 absorbed — This opened as a draft because #42 carried no ruling. Supplement 3 changed that from an unexpected direction: the integration round's outside leg reached the same sentence independently as its A12, ruled it BLOCKING false generality, the same-family leg listed the same site as a model citation, and S3-1 adjudicated what the collation calls the round's only true fork. The seed now speaks the ruling's vocabulary. The replacement says analogous constructions — one satisfaction shape over slot judgments of different kinds — with the slot judgment named as this document's own fold question rather than the substrate's, and it carries S3-1's forward clause: once the shared satisfaction predicate exists as its own committed artifact upstream, both sites cite it by digest and the analogy becomes a declared shared dependency by ordinary migration, no re-ruling owed. The translation profile routes to the encoding round. The seed's earlier phrasing — the algebra transfers, the predicate does not — is the same claim in vocabulary the candidate doesn't use. That's recorded rather than quietly swapped, since the difference between the two legs was a difference of grain and the word is what carries it. One caution I'd rather state than leave implied. S3-1's parenthetical observes that the reference implementation evaluates both ends with one class. That describes a shape, not an exercised path: as of The vector S3-1's station obligation assigns is |
|
Reconciliation census (42-6): CONVERGED with one flagged component — merge-as-record, plus one docket item. The S3-1 absorption is sound (the seed's 'analogous constructions' matches the ratified sentence). The flag: your repair 2 (the slot Pending/Declined disposition) is NOT in the ratified §9's 'unfilled slots' treatment — census finding F-6, routed to the carriage-encoding round (#57) so it isn't lost. Recommend a pointer from this PR's description to that docket entry on merge. |
Seeds the 4.2 candidate with a repair for finding #42. No ratified bytes are altered — this adds one unpinned seed document under
spec/, in the shape PR #26 established.tools/verify_kernel.pypasses 6/6.Addresses #42 without closing it. Repair 1 is in the ratified edition (§9, census round 42-6, CONVERGED); repair 2 — the slot's disposition on each pending requirement element — is not, and the census records it as F-6 with the encoding round as its plausible home. Closing #42 on this merge would discharge half the finding and lose the other half's trace, so the keyword is demoted and #42 closes when the residual is dispositioned.
Executed under adjudication S3-1 of supplement 3. When this PR opened, #42 carried no ruling. It has one now: the integration round's outside leg reached the same sentence independently as its finding A12, ruled it BLOCKING false generality, the same-family leg cited the same site as a model, and S3-1 adjudicated the round's only true fork by scoping the claim to analogous constructions. The seed is updated to the ruling's vocabulary and shape.
What section 8 claims, and what transfers
§8 (4.1 L1256–1262) says the threshold algebra is one algebra at both ends of the system, "so a verifier that can evaluate a rotation can evaluate a quorum of endorsements (a derivation from the substrate's design, not new law)."
The algebra does transfer, and the dossier specification says so in its own words: the weighted threshold is "the same fractionally weighted threshold KERI uses for key-event signing thresholds (
kt)".The satisfaction predicate does not transfer, and it is everything that decides what enters the sum. The substrate's threshold evaluator takes a list of indices of verified signatures. A dossier slot counts as
Endorsedonly when it references a signed endorsement ACDC with dispositionendorseand an appropriate act, from the expected endorser, anchored in that endorser's KEL, withsaidequal to the dossier SAID — plus, for the qualified operators, a qualification proof validating against the schema the operator'sqsfield names.A key-list offset versus a cross-log walk. The seed scopes the sentence to the algebra and adds a
SHALL NOT: an implementation may not treat the substrate's threshold evaluator as discharging §8's composed-evidence obligation.The clause underneath it was incomplete for the same reason
L1262–1267 discharges an unsatisfied group as a pending finding "whose typed requirement set enumerates exactly the unfilled slots". The cited grammar has no such state. It has three: Pending (an anticipated endorsement that has not arrived), Endorsed, and Declined (an authenticated refusal by the same candidate, recording attributable dissent).
"Unfilled" collapses Pending and Declined, and they have opposite cure paths — a pending slot is cured by the candidate acting, a declined slot is never cured by waiting. The replacement names the disposition as a fourth component of each requirement element, and cites the vocabulary rather than transcribing it, since R20 already makes the dossier threshold semantics a pinned external dependency where used.
What stays open
The species mapping. §7.2 makes species a mandatory field, and R3 puts it in the dedup key and as the final component of the canonical order — so species is load-bearing for the byte-identity
SHALLat L1037–1038. Nothing says which species a slot disposition maps to.Pendingis plausiblyabsent;Declinedis plainly not, because the bytes arrived and are authenticated. Two engines choosing differently emit requirement sets differing in a key component. That is finding #27's divergence class one tier up, and #27 resolved by ruling rather than by drafting, so this seed flags it and does not choose.The exercising fixture. #15's conformance-vector work. A three-slot group with one endorsed, one pending and one declined slot is the record that separates an engine holding the predicate from one holding only the arithmetic. §14 makes the unexercised claim a defect of this document "reviewable as such", so the narrowing is the interim and the fixture is the discharge.
What S3-1 added, and one caution
The replacement now says analogous constructions — one satisfaction shape over slot judgments of different kinds — with the slot judgment named as this document's own fold question rather than the substrate's. It also carries S3-1's forward clause: once the shared satisfaction predicate exists as its own committed artifact upstream, both sites cite it by digest and the analogy becomes a declared shared dependency by ordinary migration, with no re-ruling owed. The translation profile — slot order, issuer qualification, revoked and undisclosed slot behavior — routes to the encoding round per the same adjudication.
One caution for the drafting pass. S3-1's parenthetical observes that the reference implementation evaluates both ends with one class. That describes a shape, not an exercised path: as of
WebOfTrust/keripy@c63726654no m-ary or threshold edge-group operator exists undersrc/keri, and the only edge-operator logic is the unary set. The candidate should state the coincidence of shape without implying one evaluator has been run against both kinds of slot, which is the overclaim the repair removes.Verification
Re-read 2026-08-05 against
trustoverip/kswg-dossier-specification@3900e62andWebOfTrust/keripy@c63726654. Both are later than the revisions the engagement companion records for the 4.1 engagement surface (dossierc2d261c, keripy8e67f2e); the substance is unchanged across the interval, and the seed says so rather than implying it read the pins.The finding's own line-number citations into the dossier spec have drifted since 2026-07-30 — the claims are all still there, under section headings rather than at the cited offsets. Every citation in the seed is therefore by section name and quoted phrase. That is R20's argument arriving uninvited: the semantics did not move, the coordinates did, and only one of those survives a replay.